OASIS Collaborative Automated Course of Action Operations (CACAO) for Cyber Secu

 View Only
  • 1.  CACAO in academia and CSAF note

    Posted 08-12-2024 10:35

    Dear TC members,

    In the past couple weeks, I came across an instance of academic interest in the CACAO specification which I would like to bring to your consideration.

    A publication from Philip Empl et al. (https://link.springer.com/article/10.1007/s10207-023-00760-5) proposes parsing unstructured remediation advisory information from CSAF in the ICS domain, into CACAO playbooks. The use-case serves to support vulnerability management in ICS. In the conclusion, the authors state that CSAF and CACAO are plausible, promising resources to this end.

    On reading the paper, I thought it would be an interesting idea, perhaps, to connect CACAO playbooks more explicitly into CSAF, as possible format for the "remediations" property in the CSAF standard. I'm curious to know what you think.

    Kind regards,

    Luca

    P.S.: Partially related and FYI, another example of academic interest in CACAO: the university of Aachen, Germany, is opening Bachelor thesis projects about translating unstructured playbooks into CACAO format via LLMs.



    ------------------------------
    Luca Morgese Zangrandi
    Cybersecurity R&D
    TNO
    ------------------------------


  • 2.  RE: CACAO in academia and CSAF note

    Posted 08-12-2024 12:17
    I like the idea. Let's figure out what makes sense and how we should do it.

    Bret

    On Mon, Aug 12, 2024 at 8:35 AM Luca Morgese Zangrandi via OASIS <Mail@mail.groups.oasis-open.org> wrote:
    Dear TC members, In the past couple weeks, I came across an instance of academic interest in the CACAO specification which I would like to bring... -posted to the "OASIS Collaborative Automated Course of Action Operations (CACAO) for Cyber Security" community

    OASIS Collaborative Automated Course of Action Operations (CACAO) for Cyber Secu

    Post New Message
    CACAO in academia and CSAF note
    Reply to Group Reply to Sender via Email
    Aug 12, 2024 10:35 AM
    Luca Morgese Zangrandi

    Dear TC members,

    In the past couple weeks, I came across an instance of academic interest in the CACAO specification which I would like to bring to your consideration.

    A publication from Philip Empl et al. (link.springer.com/article/10.1007/s10207-023-00760-5) proposes parsing unstructured remediation advisory information from CSAF in the ICS domain, into CACAO playbooks. The use-case serves to support vulnerability management in ICS. In the conclusion, the authors state that CSAF and CACAO are plausible, promising resources to this end.

    On reading the paper, I thought it would be an interesting idea, perhaps, to connect CACAO playbooks more explicitly into CSAF, as possible format for the "remediations" property in the CSAF standard. I'm curious to know what you think.

    Kind regards,

    Luca

    P.S.: Partially related and FYI, another example of academic interest in CACAO: the university of Aachen, Germany, is opening Bachelor thesis projects about translating unstructured playbooks into CACAO format via LLMs.



    ------------------------------
    Luca Morgese Zangrandi
    Cybersecurity R&D
    TNO
    ------------------------------
      Reply to Group via Email   Reply to Sender via Email   View Thread   Recommend   Forward  



     
    You are subscribed to "OASIS Collaborative Automated Course of Action Operations (CACAO) for Cyber Secu" as bret.jordan.sdo@gmail.com. To change your subscriptions, go to My Subscriptions. To unsubscribe from this community discussion, go to Unsubscribe.





  • 3.  RE: CACAO in academia and CSAF note

    Posted 08-12-2024 14:10

    I also like the idea of the two standards cross-referencing each other (ie CACAO playbooks used as remediation in CSAF, and CSAF being a basis of CACAO playbooks). In my ideal world "we" (ie the CACAO, CSAF, and OCA communities) would come up with some use cases to put into the OCA Cybersecurity Automation Village, and ideally demo something at next Cybersecurity Automation Village in January (maybe with a lot of tabletop or handwaving, but ideally with working examples).



    ------------------------------
    Duncan Sparrell
    Chief Cyber Curmudgeion
    sFractal Consulting LLC
    Oakton VA
    703-828-8646
    ------------------------------



  • 4.  RE: CACAO in academia and CSAF note

    Posted 08-12-2024 14:20

    Forwarding an email thread from CACAO TC. In my ideal world described below, the 'actions' in the CACAO playbooks below would be OpenC2 commands. Note that besides the 'get SBOM' and 'patch software' commands, we could also make use cases for when the patch wasn't available yet and you had to do things like kicking off threat hunting, increasing IDS monitoring,  and denying ip's or domains (ie more restrictive rules due to higher threat level).

     

    I recommend we think about influencing the use cases to highlight the 'openc2' aspects – and then we demo some of them at the January Cybersecurity Automation Village.

     

    -- 

    Duncan Sparrell

    sFractal Consulting

    iPhone, iTypo, iApologize

    I welcome VSRE emails. Learn more at http://vsre.info/